CVE-2018-5430

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
17/04/2018
Last modified:
12/02/2025

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:*:*:* 6.2.4 (including)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:*:activematrix_bpm:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jasperreports_server:*:*:*:*:community:*:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jasperreports_server:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.3.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.3.3:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jasperreports_server:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:tibco:jaspersoft:*:*:*:*:*:aws_with_multi-tenancy:*:* 6.4.2 (including)
cpe:2.3:a:tibco:jaspersoft_reporting_and_analytics:*:*:*:*:*:aws:*:* 6.4.2 (including)